Slashdot Mirror


HBGary Hack In Depth

Udo Schmitz writes "Heise's UK site has the English translation of an article from the latest issue of their magazine c't about Anonymous's HBGary hack. It shows that there was much more involved than just social engineering to get passwords, and how anonymous evolved following OpTunisia and OpEgypt."

7 of 65 comments (clear)

  1. Lots of Security Holes by WrongSizeGlass · · Score: 4, Funny

    HBGary's systems were just riddled with security holes. From URL parameters that weren't scrubbed to straight MD5 password hashing to using the same password for several (and possibly many) accounts on different systems (servers, email, Twitter, LinkedIn, etc). I'm sure glad something as important as our government didn't use their security services. Oh, wait ... D'oh!

  2. Well that was a load of crap by AmonTheMetalhead · · Score: 5, Insightful

    Check out Ars Technica's coverage, much much better

    1. Re:Well that was a load of crap by RenHoek · · Score: 4, Informative

      It's here, in the Slashdot story that was already posted about 3 weeks ago:
      http://it.slashdot.org/story/11/02/17/0041208/Anatomy-of-the-HBGary-Hack

  3. Re:Anonymous by Anonymous Coward · · Score: 5, Insightful

    They're not a Hydra, which is a monolithic monster with no single termination point and self-repair to incremental attacks.

    They're a stand-alone complex, which is not even a single entity to begin with.

    Which makes them even harder to kill, and, to established powers they oppose, even more fearsome. (OTOH, to the extent they can be developed and manipulated to suit one's ends, they're a most powerful weapon. You can bet the shadowier sides of governments have any number of would-be Kazundo Gouda types analyzing the phenomenon.)

  4. What a waste of time by Anonymous Coward · · Score: 5, Interesting

    Don't bother reading this article, it's horribly written and not particularly correct. They make it sound like HBGary Federal was some giant security company when in reality is was a small-time 4 person company. Oh my god you broke into a 4 person company's email and the idiot manager's twitter account!

    So tired of seeing this "hack" replayed on Slashdot.

    1. Re:What a waste of time by Runaway1956 · · Score: 5, Informative

      Actually, you overplay your attempt to downplay HBGary Federal. While they never actually won any government contracts, they did have credibility with the US government, they did have access to a lot of "insider" stuff, and they were in negotiations with other contractors to provide some rather big-time stuff. They enjoyed the backing of their parent company, a major figure in the corporate world.

      Note that I do NOT claim that thier credibility was justified, nor do I claim that their wares were anything more than vaporware - but they were much, much more than some upstart company operating on less than a shoestring in someone's garage with only 4 employees.

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
  5. Re:We Can All Be Anonymous by Anonymous Coward · · Score: 5, Funny

    The first step of being anonymous would be to not sign your name at the end of a post...